Free AZ-802 sample questions with answers
Here are five free AZ-802 sample questions from five of the seven skill areas, each with the answer and the reasoning behind it. Try each one before opening the answer. These are original scenario questions written against the official skills outline, not questions from the real exam.
Question 1. A branch office has a read-only domain controller. Branch staff must be able to sign in when the WAN link is down, but the credentials of domain administrators must never be stored on the RODC. What should you configure?
- A. A fine-grained password policy for the branch users
- B. Administrator role separation on the RODC
- C. Add the branch users to the Allowed RODC Password Replication Group
- D. A second writable domain controller in the branch
Show answer
Answer: C
The Password Replication Policy decides which accounts’ passwords an RODC may cache. Adding the branch users to the Allowed RODC Password Replication Group lets them sign in offline, and privileged groups such as Domain Admins are in the Denied group by default, which takes precedence. A fine-grained password policy changes password rules, not caching. Administrator role separation delegates local administration of the RODC. A second writable DC in the branch would store every password, which is what the RODC avoids.
Want more questions like this? Full AZ-802 practice tests →
Question 2. From your workstation you open a PowerShell remoting session to SRV1 and run a command that reads a file share on SRV2. The command fails with access denied, although your account has access to the share. What is the recommended fix?
- A. Configure resource-based Kerberos constrained delegation on SRV2 for SRV1
- B. Enable WinRM on SRV2
- C. Add SRV1 to the TrustedHosts list on your workstation
- D. Connect with -Authentication Basic
Show answer
Answer: A
This is the second-hop problem: SRV1 cannot pass your credentials on to SRV2. Resource-based Kerberos constrained delegation, configured on SRV2’s computer object to trust SRV1, solves it without sending reusable credentials to SRV1. CredSSP also works but delegates your credentials to SRV1, so it is less secure. Enabling WinRM on SRV2 or adding SRV1 to TrustedHosts does not address delegation.
Want more questions like this? Full AZ-802 practice tests →
Question 3. A Hyper-V VM is replicated to a second host with Hyper-V Replica. You must prove that the replica starts and the application works, without interrupting replication or the production VM. What should you run?
- A. A planned failover
- B. An unplanned failover
- C. Reverse replication
- D. A test failover
Show answer
Answer: D
A test failover creates a separate test VM from a recovery point on the replica server, while the primary keeps running and replication continues. A planned failover requires shutting the primary down. An unplanned failover is for when the primary is lost and breaks the normal replication direction. Reverse replication is a step after a planned failover.
Want more questions like this? Full AZ-802 practice tests →
Question 4. Two DHCP servers on different sites must serve the same scope. The server in the main site should issue all leases, and the server in the branch should take over only if the main server becomes unavailable. Which configuration fits?
- A. DHCP failover in load balance mode
- B. DHCP failover in hot standby mode
- C. An 80/20 split scope
- D. The same scope created independently on both servers
Show answer
Answer: B
DHCP failover in hot standby mode has one active partner that serves clients and a standby partner that takes over when the active server is unavailable, which suits a main site with a backup server. Load balance mode shares the load between both servers. A split scope is the older method and does not replicate lease information. A second scope with the same range on each server would cause address conflicts.
Want more questions like this? Full AZ-802 practice tests →
Question 5. An administrator deleted a user account an hour ago. The AD Recycle Bin was enabled last year. You must restore the user with its group memberships intact, without taking a domain controller offline. What should you do?
- A. Perform an authoritative restore in Directory Services Restore Mode
- B. Recreate the account with the same name and add it to its groups
- C. Restore the object with Restore-ADObject
- D. Reanimate the tombstone with LDP
Show answer
Answer: C
With the Recycle Bin enabled, a deleted object keeps its attributes, including group memberships, and can be restored online with Restore-ADObject or the Active Directory Administrative Center. An authoritative restore from DSRM needs a DC restarted into DSRM and a backup. Recreating the account gives it a new SID. Reanimating a tombstone loses most attributes and is the method for domains without the Recycle Bin.
Want more questions like this? Full AZ-802 practice tests →
How did you do?
Questions 2 and 4 catch the most people. The second-hop problem looks like a permissions error, and candidates go looking at share and NTFS permissions instead of delegation. DHCP failover modes are easy to mix up when you have only ever run one server. If either slowed you down, read the hybrid management guide or the networking guide.
Question 5 is worth a second look. The exam likes to present two valid recovery methods and ask for the one that fits a constraint: online, keep memberships, no backup available.
What these questions have in common
None of them asks for a definition. Each describes a requirement and several options that all work somewhere, and the answer turns on one detail: offline sign-in without storing admin passwords, least exposure of credentials, no interruption, a standby server, no downtime. That is how most of AZ-802 reads. Underline the constraint before looking at the options.
For a longer check, take the 20-question practice test.